A new phenomenon stand out in recent years: security must pervade the entire software development lifecycle. Except it isn't. Current generation of processes and tools is lacking crucial features to properly manage modern security risks.
Think of the Log4J event. Were you able to identify all affected components? Were they internally developed, or you need a vendor support? How fast you were able to deliver a fix?
In this talk we'll explore the challenges, what you can do with current tools, and which gaps should be addressed by communities through better practices and new tools.
#Cloud #Architecture #Development #Learning #GitHub #DevOps #SoftwareEngineering #securitybreach
00:00 Introduction
08:58 Setting the scene - Context & Stats
14:27 How quickly are dependencies being patched?
22:25 How to identify vulnerabilities
29:20 Wrap-up & Context
32:15 Identifying dependencies in Cloud With Chris GitHub Organization
33:15 Further wrap-up & context